RSSAmplifier

Blog

dmpdump

CTI, threat intelligence, reverse engineering, programming, malware

dmpdump.github.ioRSS feed ↗5 posts

Latest posts

Analysis of a Low-Detection Linux Implant with Hands-On Intrusion Capabilities

UPDATE: After reviewing related infra found by @500mk500 and a related sample by @malwrhunterteam, I found quite a few similarities with the Adaptix Agent using the adaptix_gopher protocol. In early July 2026, MalwareHunterTeam shared an interesting ELF named gregbfdah.png with minimal detection in VirusTotal. The ELF was uploaded to VirusTotal on 2026-06-16 and it still has very low detection...

Linux Backdoor Targeting iKuai Routers

On July 1, 2026, MalwareHunterTeam shared an ELF uploaded to VirusTotal from Japan with 0 detection. After a quick code inspection, it was evident that the ELF was a backdoor targeting specific Linux-based devices. File name: libjson_script.so.0 SHA2: 4e6276cc400b3b9e9616d04474b64a8fa0c35375b9673ab41a92a6d5bce72d8d First uploaded to VirusTotal from Japan on 2026-06-08 The ELF impers...

PulseRAT - Google Sheets-based RAT Using UAE-India Partnership Lure

On May 19, 2026, I came across an interesting ISO uploaded from UAE. The ISO is named UAE-India_Strategic_Partnership_Week.iso, and it is likely related to the defense partnership between India and UAE announced in May 2026. The ISO contains payload that leads to a RAT which I had not seen before. I will temporarily call this RAT 'PulseRAT', but if the reader recognizes it as a known or previou...

Rebex-based Telegram RAT Targeting Vietnam

On April 1, 2026, a zip archive named CV - Vu PLPC So2156516.zip was uploaded to VirusTotal from Vietnam. This archive contains a Microsoft Compiled HTML (CHM) file named Word Document - CV - Vu PLPC KT nam 2026.chm. CHM files have historically been used by a plethora of threat actors. In my personal experience, I have seen CHM files trojanized primarily in state-sponsored/targeted activity rat...

Low Detection Linux and macOS Backdoor

In early March, MalwareHunterTeam shared a hash associated with a Linux backdoor with 0 detection in VirusTotal. It is well known that AV engines in VirusTotal do not implement the full capability of AV solutions, however, the presence of obviously malicious unobfuscated code made it an interesting finding. The backdoor has been in VirusTotal since January 27, 2026 with 2 distinct submissions, ...